Commit Graph
136 Commits
Author SHA1 Message Date
Joachim WibergandMattias Walström 59eb73bf24 confd: minor, whitespace fixes
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-06-04 13:38:03 +02:00
Mattias Walström 4f3ae3b9a4 Add new package: Rousette - a RESTConf server 2024-06-04 13:38:03 +02:00
Mattias WalströmandTobias Waldekranz bef44b725e Remove ietf-netconf-acm@2018-02-14.yang
Provided by libnetconf
2024-05-24 11:58:47 +02:00
Joachim WibergandTobias Waldekranz 809e6b44be confd: spellcheck infix-hardware.yang
Fixes #414

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-29 14:31:40 +02:00
Joachim Wiberg c3900ec710 confd: allow VLAN interfaces as bridge ports
Fixes #406

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-25 09:20:32 +02:00
Mattias Walström 5e9975f4c9 YANG: Allow any name for a routing protocol instance
Remove old limitation that only allow default

Fixes #369
2024-04-16 12:47:16 +02:00
Joachim Wiberg 4ad2948b9b confd: add deviation for /system/hostname, max 64 chars on Linux
Both IETF and POSIX allow longer hostname, 253 and 255, which Linux does
not support.  Since Linux 1.0 the maximum has been 64 US-ASCII characters.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg 4ae641d65f confd: refactor services stop/start and add web netbrowse
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg efec5f57cd confd: make web server and web console interface configurable
This commit adds an initial YANG model for Infix web services under the
infix-services.yang umbrella.  For now the nginx server statements in
/etc/nginx/nginx.conf are always on, but the backend ttyd, and the
entire nginx server can be disabled.

The default in the YANG model for both is disabled, the factory-config
has been updated to enable these services by default.

The Web Console Interface mDNS service has been updated to advertise
on port 7681, which nginx is set to forward to ttyd.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg c7e8b8f33d confd: bump infix-if-bridge version and add revision
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-09 20:22:26 +02:00
Mattias Walström c7ab09cb73 infix-if-bridge: Major refactor regarding multicast
- Rename mdb -> multicast-filters
- Add support for L2 multicast groups
- Change vlan, multicast and mulitcast-filters containers to presence
  containers. This will result in that snooping will be disabled when
  creating a bridge (or a vlan if vlan-filtered)
- Force the user to choose between VLANs and Multicast on top level bridge configuration
- Force L2 multicast to be state permanent
2024-04-04 17:27:11 +02:00
Joachim Wiberg fad75575e4 confd: add limited support for container capabilities
This change adds limited support for container capabilities.  It allows
a more fine-grained control than priviliged mode does.

Fixes #365

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-03 16:08:37 +02:00
Joachim Wiberg 662719a47f confd: fix static routes from container host interfaces (static)
In a host interface setup, i.e., moving an interface from the host to a
container, often using VETH pairs, any route should only be set when an
IP address has been set.  This because the CNI ipam plugin, which we
use, require routes be part of ipam, which in turn requires an address.

For details, see <https://www.cni.dev/plugins/current/ipam/static/>

Fixes #366

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-03 16:08:37 +02:00
Joachim Wiberg 7230c3532a confd: improve bridge port validation for VLAN filtering bridges
This patch adds validation of bridge port VLAN memberships and IP
addressing for VLAN filtering bridges:

  1. Ports must be a member of this bridge
  2. Ports cannot be tagged and untagged member at the same time
  3. A VLAN filtering bridge does not support IP addressing

A VLAN filtering bridge can only be a tagged member of a VLAN.  Any IP
addressing needs to be done using an upper VLAN interface.

NOTE: while technically possible break up these long must expressions
      into multiple must expressions per node (split at 'and'), it will
      break libyang in interesting ways that in turn make the confd
      inference functionality stop working.  E.g., creating VETH pairs.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-13 10:24:02 +01:00
Joachim Wiberg 21fd1e9442 Fix #328: drop default value for bridge-port PVID
A bridge port in a VLAN filtering bridge should be possible to configure
as "tagged only", i.e., to not assign ingressing untagged frames a VLAN
and instead drop them.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-13 10:24:02 +01:00
Joachim Wiberg ad9060e99c confd: minor, grammar fix
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-10 11:37:17 +01:00
Joachim WibergandMattias Walström f2cc620941 confd: restrict mdb group to iana-rt-types:ip-multicast-group-address
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-07 12:45:55 +01:00
Joachim WibergandMattias Walström 12eae1ec2b confd: initial mdb support, per bridge and per VLAN
Note, no VLAN id, or other VLAN specific information is contained in the
MDB entries, only forwarding information and per-port state.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-07 12:45:55 +01:00
Joachim WibergandMattias Walström 1782b12514 confd: initial multicast filtering support for bridge model
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-07 12:45:55 +01:00
Mattias WalströmandJoachim Wiberg c5d53d10a4 yang: Bump infix-routing revision 2024-03-06 18:39:27 +01:00
Mattias WalströmandJoachim Wiberg 28846dd332 Fix inconsistent naming in infix-routing model
in container: default-route-advertise
Obsolete leaf: enable
Add new leaf: enabled

enable is preferred if exist, else it use enabled.

Also update klish-plugin-sysrepo to not show the obsoleted node
in autocompletion.

This fixes #331
2024-03-06 18:39:27 +01:00
Joachim Wiberg ba25914cbe confd: add support for changing text-editor backend
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-01 14:13:43 +01:00
Joachim Wiberg 9847a8fdd1 confd: migrate infix-system:motd -> infix-system:motd-banner
Inspired by openconfig-system[1], except the infix-system type is binary
to allow encoding an entire file, with optional control characters.

The openconfig-system model also carries login-banner, which is displayed
before login.  This could be added later to infix-system to let the user
set an OpenSSH login Banner.

[1]:  https://openconfig.net/projects/models/schemadocs/yangdoc/openconfig-system.html

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-01 10:04:19 +01:00
Mattias Walström f0c23ca048 Update revision for infix-if-type 2024-02-29 10:22:32 +01:00
Richard AlpeandMattias Walström 27a4278cce statd: add good-octets counters
This patch adds out-good-octets and in-good-octets as augment in
the infix-ethernet-interface yang model. These counters represents
OctetsTransmittedOK and OctetsReceivedOK from ethtool.

Signed-off-by: Richard Alpe <richard@bit42.se>
2024-02-28 11:21:53 +01:00
Joachim Wiberg 360d3b322d confd: use podman stop/start to prevent container corruption
Sending SIGTERM to conmon is not a safe shutdown of a podman container.
To handle gracefully handle shutdown, restarting and provide an orderly
start of dependencies, we use the Finit sysv trick via container script
wrapper to call 'podman stop foo'.

However, since podman does not support syslog as output for containers
we employ an old FIFO trick with another program, k8s-logger, to allow
logs to reach syslog.  Please note that k8s-logger must have properly
started before we call `podman start` -- this makes us fully dependent
on the 'container' wrapper script.  Hence the documentation update.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg e4aa36dfe7 confd: tighten up container data validation in YANG model
Review found quite a few strings that could be given an obvious pattern
or specialized sub-type, e.g. inet:ip-address, to restrict the input
data validation.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 34b06fa448 confd: update container documentation and YANG models
Due to the deprecation of CNI i Podman[1], and its upcoming removal in
Podman v5.0, we decided to cut our losses and modify all documentation
and models to become backend neutral.  We will continue to use CNI as
long as possible -- it gives us host interfaces, for instance, that is
not part of netawark yet, it seems.

Also, sync mount and volume documentation with YANG model changes.

[1]: https://blog.podman.io/2023/11/cni-deprecation-and-removal-from-podman-5-0/

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 81d8643a6f confd: rename container 'file' to 'mount', add more mount types
After discussions in the development team, and an external demo, we
decided to rename file mounts to just mounts and adopt established
nomenclature.

With this change we now allow mounting any type of file or directory
from the host to the container, for regular files/directories a bind
mount is used.  We also introduce 'source' and 'type', to support
mounting of host files and directories, the destination path has been
renamed to 'target'.  The mount cousin, 'volume', which basically is a
specialized mount, has also been updated to use 'target'.

The 'source' and 'content' are now hidden behind a YANG choice to ensure
users can only use them the intended way (either/or not both).

Initial models had 'destination' (path) as mandatory, with this change
we can reintroduce that to ensure this proper configurations.

The documentation in both YANG model and markdown has been updated,
significantly, to provide lots of examples.

Please note, glob style mounts have not been tested, at all.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 61cba2615f confd: make container privileged mode configurable
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg a6f6fcac6a confd: add support for oci: and oci-archive: images
1. add support for extracting, and finding the directory holding the
    index.json metadata file in, OCI images.  An archive in Infix is either
    a .tar or .tar.gz archive, which we need to unpack for this version of
    podman to be able to load them.
 2. new RPC '/infix-containers:oci-load' calls 'container load' of an
    OCI archive (tarball), optionally gzipped.  The resulting image uses
    the directory name of the unpacked tarball, so the container script
    offers a way to retag the image after loading it.

First class citizens in container transport are docker:// and the OCI
family of URI:s.  A docker:// URL, or a local docker-archive:path, is
assumed to be well formed, in which case we leave it up to podman to
handle.

Note: 'podman import' does not fully understand OCI formats.  It drops
      ENTRYPOINT and COMMAND, while 'podman load' handles things a lot
      better.  Only letdown is it does not support nameing the image.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 8ea159ce5d confd: add feature flag for containers
Not all customers want Container support in their Ínfix builds.  This
patch adds build-time support for detecting if podman is enabled in
the configuration.

 - Klish container commands have been broken out to their own xml file
 - infix-interfaces have been given a 'containers' feature
 - ietf-interfces.c enables 'containers' feature on an #ifdef
 - infix-container.c is only built if --enable-containers

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 235d3e46e6 confd: major refactor of infix-containers after team review
- Rename container/container -> containers/container
 - Collapse containers-state into containers
 - Complete refactor of network/host-network for improved UX.  A new
   must expression ensure mutual exclusion between host and networks
 - Rename entrypoint -> command, for consistency (overrides ENTRYPOINT)
 - Move nodes around a bit for more logical placement in model
 - Clean out all traces of a container on removal
 - Rename container image_id -> image-id for consistency

The active queue is for tracking currently running containers, ensuring
only relevant changes are applied, and also for container image upgrade,
at the end of which these scripts are re-run to activate the new image

Also, fix misplaced '-f' when pruning unused volumes.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg a9a7b7016d statd: initial support for container-state information
Also, add missing dependency on libite to packaging.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg b7d119b23f confd: add NETCONF actions to start/stop/restart containers
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg ff32314676 confd: rename volume dir -> path, same as bind-mounted files
Also, update container YANG model descriptions and ensure 'path' is
mandatory for each list element and attach a regexp pattern to fix
the mountpoint to an absolute path inside the container.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg cd4e8b0a9f confd: add support for mounting read-only files in containers
In the container configuration context:

    edit file ntp.conf
    set path /etc/ntp.conf
    set content

The last command opens a text editor where you can paste the contents
of the file.  This is stored base64 encoded in the datastore as well
as in JSON/XML.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg aafa88b648 confd: add support for container volumes
This commit adds support for writable container volumes.  A volume, when
compared to a mount, is a writable directory created when the container
starts and is automatically rsync'ed with the underlying directory it
is mounted on on first use.  A mount otoh does not rsync so it results
only in an empty directory inside the container.

The podman/docker mount feature will be used later to bind mount single
files or sharing directories from the host, e.g., /sys/class/leds/ to
one of more containers.

Note: unused volumes are automatically pruned.  Hence, a volume
      currently cannot be moved to another container.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 256c462c0c confd: add support for read-only containers
This creates a container without a writable layer.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg d8dde9cde2 confd: add support for custom container ENTRYPOINT
This was a tough nut to crack.  Turns out the trick to changing the
ENTRYPOINT is to set --entrypoint=command and then call 'podman create
... command args'.  Not entirely obvious since the documented approach
is to use a JSON array as the argument: podman create
--entrypoint='["command", "args" ]'.

Admittedly, encoding this in C to transfer it via a POSIX shell script
to the command line, is not the easiest task I've undertaken.  So I gave
up and found this workaround.

Worth noting, however, is that one *must* set `--entrypoint`, it is not
enough to just append the command to the 'podman create' command line.
Due to differences in docker and podman, we cannot supply the full args
to an alternate entrypoint command.  But for the command to actually run
we need to override the image's ENTRYPOINT and send the command and args
as the last arguments on the command line to podman create.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg aa7ea66a0d confd: add support for setting container hostname
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 7a57d4f0fa confd: add support for container environment variables
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 3d85eba3fc confd: add support for publishing container ports
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg b04c81199d confd: add support for host containers, shares host's interfaces
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg ffd2128614 confd: add support for container restart and restart policy
Also, ensure the deleted container is actually deleted before recreating
it with a new configuration.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 9e801dfa2f confd: initial support for Docker containers using podman
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Mattias Walström 5e707753e9 ietf-hardware: YANG: Deviate everything not supported yet 2024-02-23 14:01:23 +01:00
Richard AlpeandTobias Waldekranz 1da00a9764 yang: add stp-state to infix-if-bridge
Signed-off-by: Richard Alpe <richard@bit42.se>
2024-02-20 21:43:48 +01:00
Richard AlpeandJoachim Wiberg 198be2a9c6 confd: add new interface type "etherlike"
Needed for devices that share a lot of properties with an ethernet
device but doesn't support "ethtool" and such. An example is TAP
interfaces.

Signed-off-by: Richard Alpe <richard@bit42.se>
2024-02-05 18:01:30 +01:00
Joachim WibergandTobias Waldekranz 307cdb02b4 confd: bump infix-dhcp-client YANG model version for release
The DHCP client YANG model saw a lot of changes added in the 23.12
sprint, fortunately there was never an official release.

This commit bumps the model version for v24.01.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-30 15:32:38 +01:00